Business security policy generation method, apparatus, device, and storage medium

By generating security attribute tables and matching risk policies, the problem of mismatch between security policies and business needs was solved, achieving accurate security threat identification and policy matching, and improving the security and efficiency of business processing.

CN119312406BActive Publication Date: 2025-11-21INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311102141.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-30
Publication Date
2025-11-21
Estimated Expiration
2043-08-30

AI Technical Summary

Technical Problem

In existing technologies, security strategies are designed from the perspective of overall business processing, but it is impossible to determine corresponding security strategies for different business needs. This results in a mismatch between security strategies and business needs, and there are problems such as missing or overly complex security strategies.

Method used

A security attribute table is generated based on the data type of the business data. The target attribute data is determined, risk policies are matched from the preset risk database, and a business security policy model is generated by combining the risk policies and the handling policies.

Benefits of technology

It enables a comprehensive and accurate identification of potential security threats, ensuring that security strategies match business needs and avoiding security vulnerabilities and issues of ease of use or excessive cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119312406B_ABST
    Figure CN119312406B_ABST
Patent Text Reader

Abstract

The present disclosure provides a business security policy generation method, device, equipment and storage medium, which can be applied to the field of information security technology and the field of financial technology. The business security policy generation method comprises: in response to receiving business data, generating a security attribute table based on the data type of the business sub-data included in the business data; determining target attribute data from a plurality of attribute data included in the security attribute table; determining a risk policy corresponding to the target attribute data from a preset risk database, wherein the preset risk database comprises an association relationship between the target attribute data and the risk policy; and determining a business security policy model based on the risk policy and a target processing policy corresponding to the risk policy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of information security technology and financial technology, and in particular to a business security policy generation method, apparatus, device, medium and program product. Background Technology

[0002] With the rapid development of internet technology, many companies have gradually shifted their business processes from offline to online. While online business processes offer convenience, they also generate numerous security threats. Addressing these threats typically involves designing security strategies from the perspective of the overall business process.

[0003] In realizing the concept disclosed herein, the inventors discovered at least the following problems in the related technology: by determining the security strategy from the perspective of overall business processing, it is impossible to determine the corresponding security strategy for different business needs, resulting in a mismatch between the security strategy and business needs in business processing. Summary of the Invention

[0004] In view of the above problems, this disclosure provides a business security policy generation method, apparatus, device, medium and program product.

[0005] According to a first aspect of this disclosure, a method for generating a business security policy is provided, comprising: in response to receiving business data, generating a security attribute table based on the data type of business sub-data included in the business data; determining target attribute data from multiple attribute data included in the security attribute table; determining a risk policy corresponding to the target attribute data from a preset risk database, wherein the preset risk database includes the association relationship between the target attribute data and the risk policy; and determining a business security policy model based on the risk policy and a target processing policy corresponding to the risk policy.

[0006] According to an embodiment of this disclosure, generating a security attribute table based on the data type of the business sub-data included in the business data includes: determining a first target business sub-data based on the data type of the business sub-data included in the business data; determining risk sub-data based on the data format of the first target business sub-data; and generating a security attribute table based on the risk sub-data and a second target business sub-data, wherein the second target business sub-data is business sub-data other than the first target business sub-data in the business sub-data.

[0007] According to embodiments of this disclosure, the data format of the aforementioned target business sub-data includes a file format, and the aforementioned target business sub-data includes multiple data headers; the determination of risk sub-data based on the data format of the aforementioned target business sub-data includes: when the data format of the aforementioned target business sub-data is a file format, determining a target data header from the multiple data headers based on a preset data identifier; determining candidate risk data based on the aforementioned target data header; determining target candidate risk data from the candidate risk data based on a regular expression; and determining risk sub-data from the multiple target candidate risk data based on a preset risk data table.

[0008] According to embodiments of this disclosure, the data format of the target business sub-data includes a text format; determining risk sub-data based on the data format of the target business sub-data includes: when the data format of the target business sub-data is text, segmenting the target business sub-data into words to obtain at least one sub-data segmentation sequence; inputting the at least one sub-data segmentation sequence into a trained language model to obtain a probability value that the sub-data segmentation sequence is the risk sub-data; and when the probability value is greater than or equal to a target threshold, using the sub-data segmentation sequence as the risk sub-data.

[0009] According to embodiments of this disclosure, the security attribute table includes security types corresponding to the security attribute table; determining target attribute data from multiple attribute data included in the security attribute table includes: determining a target title from the security data table based on the security type; and determining the target attribute data based on the target title.

[0010] According to embodiments of this disclosure, the aforementioned security attribute table is at least one, and the method further includes: determining a target security attribute table whose security type is a geographic security type and an object security type; and generating a security trust model based on the aforementioned target security attribute table, so as to determine trusted objects in the business processing based on the aforementioned security trust model.

[0011] According to embodiments of this disclosure, the above-mentioned determination of the risk strategy corresponding to the target attribute data from the preset risk database includes: matching the target attribute data with the preset risk database to obtain a matching result; determining the risk category of the target attribute data when the matching result indicates that the target attribute data exists in the preset risk database; and determining the risk strategy based on the risk category, wherein the risk category includes sensitive information risk, identity authentication risk, resource abuse risk, and transaction risk.

[0012] According to embodiments of this disclosure, determining a business security strategy model based on the aforementioned risk strategy and the corresponding processing strategy includes: generating a strategy summary based on the aforementioned risk strategy; matching the strategy summary in a preset strategy table to obtain a matching result; determining a target processing strategy corresponding to the strategy summary when the matching result indicates that the strategy summary exists in the preset strategy table, wherein the preset strategy table includes multiple preset risk strategies and multiple preset processing strategies; and generating the aforementioned business security strategy model based on the aforementioned risk strategy and the target processing strategy.

[0013] A second aspect of this disclosure provides a business security policy generation apparatus, comprising: a security attribute generation module, configured to generate a security attribute table based on the data type of business sub-data included in the received business data; a target data determination module, configured to determine target attribute data from multiple attribute data included in the security attribute table; a risk policy determination module, configured to determine a risk policy corresponding to the target attribute data from a preset risk database, wherein the preset risk database includes the association relationship between the target attribute data and the risk policy; and a policy model determination module, configured to determine a business security policy model based on the risk policy and a target processing policy corresponding to the risk policy. A third aspect of this disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the business security policy generation method.

[0014] A fourth aspect of this disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the above-described business security policy generation method.

[0015] The fifth aspect of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described business security policy generation method.

[0016] According to embodiments of this disclosure, in response to receiving business data, a security attribute table is generated based on the data type of the business sub-data included in the business data. Target attribute data is determined from multiple attribute data included in the security data table. Then, a risk policy corresponding to the target attribute data is determined from a preset risk database. Based on the risk policy and the corresponding processing policy, a business security policy model is determined. This allows for the determination of a business security policy model that includes the risk policy and its corresponding processing policy. Because the security attribute table is generated based on the data type of the business sub-data, the dispersed business sub-data is categorized and summarized. Therefore, target attribute data that may pose security risks can be quickly identified from the security attribute table. The risk policy corresponding to the target attribute data is then matched from the preset risk database. Finally, the business security policy model is determined based on the risk policy and its corresponding target processing policy. Therefore, this at least partially solves the technical problem of mismatch between security policies and business requirements, enabling a comprehensive and accurate identification of potential security threats and a precise and comprehensive determination of the security policy corresponding to the security threat, thereby better ensuring the security and stability of business processing. Attached Figure Description

[0017] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0018] Figure 1 The illustration schematically depicts application scenarios of the business security policy generation method, apparatus, device, medium, and program product according to embodiments of this disclosure.

[0019] Figure 2 A flowchart illustrating a business security policy generation method according to an embodiment of this disclosure is shown schematically.

[0020] Figure 3 A flowchart illustrating the generation of a security attribute table according to an embodiment of the present disclosure is shown schematically.

[0021] Figure 4 A flowchart illustrating the generation of a secure trust model according to an embodiment of this disclosure is shown.

[0022] Figure 5 A schematic diagram illustrating a security trust model according to an embodiment of the present disclosure is shown.

[0023] Figure 6 A schematic diagram of a security trust model according to another embodiment of this disclosure is shown.

[0024] Figure 7 A schematic block diagram of a business security policy generation apparatus according to an embodiment of the present disclosure is shown.

[0025] Figure 8 A block diagram schematically illustrates an electronic device suitable for implementing a business security policy generation method according to an embodiment of the present disclosure. Detailed Implementation

[0026] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0027] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0029] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).

[0030] In the technical solution of this invention, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0031] The research revealed that while online business processes offer convenience, they also generate numerous security threats. Often, security strategies are designed from the perspective of the overall business process, rather than addressing specific threats to business data within particular business scenarios. Consequently, the security policy definitions for business processing systems or applications are relatively weak, potentially leading to a mismatch between security policies and business needs. For example, some security policies may be missing or too lenient, resulting in insufficient security authentication in certain business scenarios and numerous vulnerabilities; conversely, some security policies may be overly complex, compromising usability or increasing costs.

[0032] Embodiments of this disclosure provide a method for generating a business security policy, comprising: in response to receiving business data, generating a security attribute table based on the data type of business sub-data included in the business data; determining target attribute data from multiple attribute data included in the security attribute table; determining a risk policy corresponding to the target attribute data from a preset risk database, wherein the preset risk database includes the association relationship between the target attribute data and the risk policy; and determining a business security policy model based on the risk policy and a target processing policy corresponding to the risk policy.

[0033] Figure 1 The illustration schematically depicts application scenarios of the business security policy generation method, apparatus, device, medium, and program product according to embodiments of this disclosure.

[0034] like Figure 1 As shown, application scenario 100 according to this embodiment may include terminal devices 101, 102, and 103, a network 104, and a server 105. Network 104 serves as a medium for providing a communication link between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0035] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0036] Terminal devices 101, 102, and 103 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0037] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using terminal devices 101, 102, and 103 (for example only). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0038] It should be noted that the business security policy generation method provided in this disclosure embodiment can generally be executed by server 105. Correspondingly, the business security policy generation apparatus provided in this disclosure embodiment can generally be located in server 105. The business security policy generation method provided in this disclosure embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105. Correspondingly, the business security policy generation apparatus provided in this disclosure embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105.

[0039] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0040] The following will be based on Figure 1 The described scene, through Figures 2-6 The method for generating business security policies according to the disclosed embodiments is described in detail.

[0041] Figure 2 A flowchart illustrating a business security policy generation method according to an embodiment of this disclosure is shown schematically.

[0042] like Figure 2 As shown, the business security policy generation method includes operations S210 to S240.

[0043] In operation S210, in response to receiving business data, a security attribute table is generated based on the data type of the business sub-data included in the business data.

[0044] According to embodiments of this disclosure, upon receiving business data, a security attribute table can be generated based on the data type of the business sub-data included in the business data. There is no limitation on the number of security attribute tables generated; there can be multiple tables or just one table.

[0045] According to the embodiments of this disclosure, the specific data type of business data is not limited, and it can be any business-related data, such as business architecture data, which is the data used as the basis for system or program development.

[0046] According to embodiments of this disclosure, the data type of business sub-data is not limited; it may include multiple data types or only one data type.

[0047] According to embodiments of this disclosure, the data types of business sub-data include: asset type, time type, region type, business type, and object type. The names of the business sub-data can correspond to system asset data, time information data, region information data, business process data, and stakeholder data, respectively.

[0048] According to embodiments of this disclosure, system asset data can be object data that needs to be protected in the business scenario of business data, such as user funds, user data, etc.

[0049] According to embodiments of this disclosure, time information data can be time attribute data related to functions in the business scenario of business data, such as system running time, certificate validity period, etc.

[0050] According to embodiments of this disclosure, the geographic information data can be geographically related data in the business scenario of the business data, such as: whether the system or business is published domestically or overseas, online or offline.

[0051] According to embodiments of this disclosure, business process data refers to the data of business processes that need to be executed when processing business in a business scenario.

[0052] According to embodiments of this disclosure, stakeholder data refers to information about various participants in a business scenario, such as individual customers, banks, and telecom operators.

[0053] According to embodiments of this disclosure, the security type of the security attribute table generated for different types of business sub-data is different. For example, the security attribute table generated for time information data has a time security type, and the security attribute table generated for regional information data has a regional security type.

[0054] According to embodiments of this disclosure, a security attribute table generated from business sub-data based on business data can better summarize business sub-data and describe business operations, thereby more conveniently identifying potential security vulnerabilities in business scenarios.

[0055] In operation S220, the target attribute data is determined from the multiple attribute data included in the security attribute table.

[0056] According to embodiments of this disclosure, a security attribute table typically includes multiple attribute data and is divided into different groups according to the characteristics of the attribute data, with each group including its own title.

[0057] According to embodiments of this disclosure, for security attribute tables of different security types, target data can be determined from target titles that match the preset title data table based on a preset title data table. The preset title data table is a table that stores data titles corresponding to data that may have vulnerabilities in security attribute tables of different security types.

[0058] According to embodiments of this disclosure, by determining the target title, target attribute data can be identified more quickly and accurately among multiple attribute data included in the security attribute table.

[0059] In operation S230, the risk strategy corresponding to the target attribute data is determined from the preset risk database. The preset risk database includes the association between the target attribute data and the risk strategy.

[0060] According to embodiments of this disclosure, by matching target attribute data in a preset risk database, the risk strategies that may correspond to the target attribute data can be obtained.

[0061] According to embodiments of this disclosure, different target attribute data correspond to different risk categories, and different risk categories correspond to different risk strategies.

[0062] According to embodiments of this disclosure, after determining the risk category corresponding to the target attribute data, candidate risk strategies corresponding to the risk category can be determined from a preset risk database, and first attribute data associated with the target attribute data can be queried in a security attribute table based on the target attribute data, thereby further filtering the candidate risk strategies based on the first attribute data to obtain a risk strategy.

[0063] According to the embodiments of this disclosure, the risk strategies corresponding to the target attribute data can be determined from the preset risk database. This can comprehensively determine the risk strategies that may exist for the target attribute data, thereby further ensuring the determination of the risk strategies required in the business scenario and avoiding the existence of risk vulnerabilities.

[0064] In operation S240, a business security strategy model is determined based on the risk strategy and the target processing strategy corresponding to the risk strategy.

[0065] According to embodiments of this disclosure, a processing strategy corresponding to a risk strategy can be determined from a preset strategy table based on the risk strategy. This ensures that different risks or threats in the business security strategy model have corresponding solutions, reducing the possibility of mismatch between the processing strategy and the risk strategy, and enabling subsequent security strategy implementation to be guided from business planning.

[0066] According to embodiments of this disclosure, in response to receiving business data, a security attribute table is generated based on the data type of the business sub-data included in the business data. Target attribute data is determined from multiple attribute data included in the security data table. Then, a risk policy corresponding to the target attribute data is determined from a preset risk database. Based on the risk policy and the corresponding processing policy, a business security policy model is determined. This allows for the determination of a business security policy model that includes risk policies and corresponding processing policies. Because the security attribute table is generated based on the data type of the business sub-data, the dispersed business sub-data is categorized and summarized. Therefore, target attribute data that may pose security risks can be quickly identified from the security attribute table. The risk policy corresponding to the target attribute data is then matched from the preset risk database. Finally, the business security policy model is determined based on the risk policy and the corresponding target processing policy. Thus, this at least partially solves the technical problem of inaccurate security policy design, achieving the technical effect of comprehensively and accurately identifying potential security threats and determining comprehensive and accurate security policies for potential security threats.

[0067] Figure 3 A flowchart illustrating the generation of a security attribute table according to an embodiment of the present disclosure is shown schematically.

[0068] like Figure 3 As shown, generating the security attribute table includes operations S211 to S213.

[0069] In operation S211, the first target business sub-data is determined based on the data type of the business sub-data included in the business data.

[0070] In operation S212, risk sub-data is determined based on the data format of the first target business sub-data.

[0071] In operation S213, a security attribute table is generated based on the risk sub-data and the second target business sub-data, wherein the second target business sub-data refers to the business sub-data other than the first target business sub-data.

[0072] According to embodiments of this disclosure, the data type of the first target business sub-data can be business process data.

[0073] According to embodiments of this disclosure, the data format of the first target business sub-data may include a file format and a text format.

[0074] According to embodiments of this disclosure, different processing schemes can be determined based on the data format of the first target sub-data, and risk sub-data can be determined by processing the first target sub-data based on the processing scheme.

[0075] According to embodiments of this disclosure, security attribute tables of different security types can be constructed based on risk sub-data and second target business sub-data. The method of constructing the security attribute tables is not limited; it can involve extracting target business sub-data, matching the second target business sub-data or risk sub-data with a preset attribute data table, and determining the data associated with the second target business sub-data or risk sub-data. For example: when the data type of the second target business sub-data is time-based, a time-based security attribute table is generated, as shown in Table 1; when the data type of the second target business sub-data is region-based, a region-based security attribute table is generated, as shown in Table 2; when the data type of the second target business sub-data is object-based, an object-based security attribute table is generated, as shown in Table 3; and when a security attribute table for object-risk types is generated from risk sub-data, as shown in Table 4.

[0076] Table 1

[0077] Time type Business type Certification basis Authorization Expiry Date Log in Certificate validity period Record retention time Query Storage duration

[0078] Table 2

[0079] channel area Access method Web page worldwide external network Mini Program Within the territory external network

[0080] Table 3

[0081] Stakeholders Classification Authentication method individual customers individual customers Identity Authentication Third-party payment payment institutions Interface Authentication

[0082] Table 4

[0083] Risk data Business Scenarios Data types Bank card number Withdrawal / Deposit / Transfer Sensitive data ID number Identity verification Privacy data

[0084] According to the embodiments of this disclosure, Tables 1 to 3 are only illustrative. The amount of attribute data and title names in Tables 1 to 3 are not limited. Security attribute tables with different attribute data or title names can be obtained according to business needs.

[0085] According to an embodiment of this disclosure, taking the generation of a security attribute table as shown in Table 3 as an example: based on the second target business sub-data under the stakeholder title, it is matched with a preset attribute data table to obtain classification data and authentication method data associated with individual customers, as well as classification data and authentication method data associated with third-party payment. The obtained data are classified and summarized to obtain the security attribute table as shown in Table 3.

[0086] According to the embodiments of this disclosure, since the first target business sub-data may include risk sub-data that poses a risk during business processing, and the risk sub-data cannot be directly obtained based on the first target business sub-data, it is necessary to reprocess the first target business sub-data to directly obtain the risk sub-data. This achieves a comprehensive determination of the risk sub-data hidden in ordinary data, and generates a security attribute table based on the risk sub-data or business sub-data of other data types. This achieves a classification and summary of potential threats or hidden risks, facilitating subsequent classification processing and thus ensuring the security of the business scenario.

[0087] According to embodiments of this disclosure, the data format of the target business sub-data includes a file format, and the target business sub-data includes multiple data headers; determining risk sub-data based on the data format of the target business sub-data may include the following operations.

[0088] When the target business sub-data is in file format, the target data title is determined from multiple data titles based on a preset data identifier; candidate risk data is determined based on the target data title; target candidate risk data is determined from the candidate risk data based on a regular expression; and risk sub-data is determined from multiple target candidate risk data based on a preset risk data table.

[0089] According to embodiments of this disclosure, when the target business sub-data is in file format, the target business sub-data includes multiple data headers, and the data queue in the target business sub-data can be read based on the data headers.

[0090] According to embodiments of this disclosure, based on a preset data identifier, a target data title can be determined from multiple data titles, and the coordinate value corresponding to the target data title can be determined from the file index of the target business sub-data, thereby obtaining the location of the target data title. The file index includes multiple data titles and the coordinate values ​​corresponding to each data title.

[0091] According to embodiments of this disclosure, the position of the target data title in the target business sub-data can be determined based on the location of the target data title, thereby determining the data content included at that position and using that data content as candidate risk data.

[0092] According to embodiments of this disclosure, candidate risk data is matched with a preset regular expression to determine multiple target candidate risk data from the acquired risk data, such as bank card information, mobile phone number, ID card number, etc. Then, the target candidate risk data is filtered through a preset risk data table to remove data that meets the regular expression but does not pose a risk or that has a matching error with the regular expression, thereby obtaining risk sub-data.

[0093] According to embodiments of this disclosure, when the target business sub-data is in file format, by determining the target data title, candidate risk data under the target data title is obtained from the undetermined target data title, and the candidate risk data is filtered by regular expression matching to obtain target candidate risk data. In order to ensure the integration with the business scenario and to avoid target candidate risk data obtained due to errors, the target candidate risk data is further filtered by a preset risk data table, thereby obtaining more accurate risk sub-data with a high degree of integration with the business scenario.

[0094] According to embodiments of this disclosure, the data format of the target business sub-data includes a text format; determining risk sub-data based on the data format of the target business sub-data may include the following operations.

[0095] When the target business sub-data is in text format, the target business sub-data is segmented into words to obtain at least one sub-data segmentation sequence; the at least one sub-data segmentation sequence is input into a trained language model to obtain the probability value of the sub-data segmentation sequence being risky sub-data; if the probability value is greater than or equal to the target threshold, the sub-data segmentation sequence is used as risky sub-data.

[0096] According to embodiments of this disclosure, when the data format of the target business sub-data is text format, the target business sub-data is segmented into words. For example, if the target business sub-data is "Please enter SMS verification code", the word segmentation of the target business sub-data can be as follows: "Please|Enter|SMS|Verification Code".

[0097] According to embodiments of this disclosure, a segmentation sequence is constructed for the target business sub-data after word segmentation. The number of words included in each sequence is not limited and can be determined based on the language model into which the sub-data segmentation sequence is to be input.

[0098] According to embodiments of this disclosure, the sub-data segmentation sequence is input into a trained language model, and the semantic similarity between the sub-data segmentation sequence and the risk sub-data is calculated. The probability value of each sub-data segmentation sequence being a risk sub-data can be obtained. The language model is not limited and can be any language model that yields the probability value of the sub-data segmentation sequence being a risk sub-data, such as n-gram.

[0099] According to embodiments of this disclosure, the number of words in each sub-data segmentation sequence can be determined by n. For example, if the language model is 2-gram, then for "Please|Enter|SMS|Verification Code", one possible sub-data segmentation sequence is {Please, Enter}, {SMS, Verification Code}.

[0100] According to embodiments of this disclosure, the trained language model is a language model obtained by fully training the sample sub-data word segmentation sequence and labels.

[0101] According to embodiments of this disclosure, the target threshold is not limited, and an appropriate target threshold can be set according to the actual situation.

[0102] According to embodiments of this disclosure, for target business sub-data in text format, risk sub-data can be obtained quickly and accurately by performing word segmentation and inputting into a trained word segmentation model.

[0103] According to embodiments of this disclosure, risk sub-data is extracted from target business sub-data with different data formats by using different extraction methods, thereby improving the accuracy and comprehensiveness of extracting risk sub-data from target business sub-data.

[0104] According to embodiments of this disclosure, a security attribute table includes security types corresponding to the security attribute table; determining target attribute data from multiple attribute data included in the security attribute table may include the following operations.

[0105] Based on the security type, determine the target title from the security data table; based on the target title, determine the target attribute data.

[0106] According to the embodiments of this disclosure, since the target attribute data of the security attribute table is not the same for different security types, when determining the target attribute data, it is necessary to first determine the security type of the security data line table, and then determine the target title to which the useful data belongs through the preset title data table, so that the attribute data belonging to the target title is used as the target attribute data.

[0107] According to embodiments of this disclosure, the target attribute data can be determined conveniently, quickly, and accurately using the above method.

[0108] Figure 4 A flowchart illustrating the generation of a secure trust model according to an embodiment of this disclosure is shown.

[0109] like Figure 4 As shown, there is at least one security attribute table, and the method may further include operations S410 to S420.

[0110] In operation S410, the target security attribute table is determined with security types of geographic security type and object security type.

[0111] In operation S420, a security trust model is generated based on the target security data table, so as to identify trusted objects in the business process based on the security trust model.

[0112] According to embodiments of this disclosure, a security trust model can be generated by determining the relationships between stakeholders, between different regions, and between stakeholders and regions, as well as the required authentication methods, through a target security attribute table with security types of regional security and object security.

[0113] Figure 5 A schematic diagram illustrating a security trust model according to an embodiment of the present disclosure is shown.

[0114] like Figure 5 As shown, in actual business scenarios, individual customers may make payments through third-party payment platforms. When using a third-party payment platform, the platform needs to determine whether the individual customer has authorized the transaction, whether identity verification is required, and whether the individual customer corresponds to the user management information. Additionally, the NetsUnion payment platform needs to verify the identity of the third-party payment platform. If the verification, authorization, and authentication results are all satisfactory, the trust relationship between the individual customer, the third-party payment platform, and the NetsUnion payment platform is considered reliable. NetsUnion is a non-bank payment institution online payment clearing platform.

[0115] According to embodiments of this disclosure, a transaction relationship may exist between an individual customer and a merchant. Before a transaction is conducted, it is necessary to determine the merchant's information. The individual customer needs to authenticate, authorize, and verify the merchant's credibility. Similarly, if a transaction relationship has been established between the merchant and the UnionPay payment platform, the UnionPay payment platform needs to verify the merchant. If the authentication and authorization are both successful, it can be determined that the trust relationship between the individual customer, the merchant, and the UnionPay payment platform is credible.

[0116] According to embodiments of this disclosure, when individual customers use various internet platforms, the same internet platforms also need to perform user management and authentication actions such as login for individual customers, and require authorization confirmation between users and internet platforms regarding their respective permissions. Furthermore, internet platforms need to transact with operators to obtain network resources from the operators. The operators will authenticate the internet platforms to determine whether they are platforms that can use network resources. At the same time, risk monitors will monitor the internet platforms to perform risk control and auditing, thereby determining whether each object is trustworthy based on the above process.

[0117] According to embodiments of this disclosure, individual customers can also conduct transactions or handle business through bank tellers. When conducting transactions, tellers need to perform user management, authorization, identity authentication, and identification of other information for individual customers. Tellers can be identified by bank branches, and the bank branch business can also be identified by the NetsUnion payment platform and UnionPay payment platform. Thus, if there are no problems in each authorization, authentication, and identification process, all objects are trustworthy.

[0118] According to embodiments of this disclosure, a security trust model can be used to determine whether each object is trustworthy during business processing and what authentication is required for an object to be trustworthy. This enables the system to alert trusted objects. In actual business processing, if there are trust relationships between stakeholders that do not conform to the security information model, warnings can be issued.

[0119] According to embodiments of this disclosure, a security trust model can be used to determine whether each stakeholder in each process node is trustworthy during subsequent actual business processing, thereby accelerating the security of business processing and minimizing business risks caused by incorrect trust relationships.

[0120] According to embodiments of this disclosure, determining a risk strategy corresponding to target attribute data from a preset risk database may include the following operations.

[0121] The target attribute data is matched with a preset risk database to obtain the matching results. If the matching results indicate that the target attribute data exists in the preset risk database, the risk category of the target attribute data is determined. Based on the risk category, a risk strategy is determined. The risk categories include sensitive information risk, identity authentication risk, resource abuse risk, and transaction risk.

[0122] According to embodiments of this disclosure, by matching target attribute data in a preset risk database, the risk category corresponding to the target attribute data can be determined. Through the association between risk categories and risk strategies included in the preset risk database, the risk strategy corresponding to the target attribute data can be directly determined.

[0123] According to embodiments of this disclosure, an initial risk strategy corresponding to the risk category can be determined from a preset risk database by using the risk category corresponding to the target attribute data, and then attribute data associated with the target attribute data can be determined through a security attribute table to filter the initial risk strategy, thereby obtaining a more accurate risk strategy.

[0124] According to embodiments of this disclosure, different risk strategies are applied based on different risk categories, including sensitive information risk, authentication risk, resource misuse risk, and transaction risk.

[0125] According to embodiments of this disclosure, sensitive information risks may include sensitive information leakage risks, sensitive information input risks, and privacy protection risks.

[0126] According to embodiments of this disclosure, the risk of sensitive information leakage refers to the possibility of sensitive information leakage. When the risk category of the target attribute data is sensitive information risk, the sensitivity level classification of the target attribute data can be determined. Different risk strategies should be adopted for target attribute data with different sensitivity levels. For example, when the sensitivity level of the target attribute data is high, the risk strategy may be to not display all of the target attribute data.

[0127] According to embodiments of this disclosure, the risk of sensitive information input can be the risk category corresponding to the target attribute data input by the user, such as input information, written information, etc.

[0128] According to embodiments of this disclosure, privacy protection risks can be risk categories corresponding to target attribute data related to user privacy data. The target attribute data can be privacy data such as name and age. The strategy corresponding to privacy protection risks can be prompting where to perform privacy protection.

[0129] According to embodiments of this disclosure, identity authentication risks may also include different types of sub-identity authentication risks, such as facial recognition authentication risks, bank card account password authentication risks, etc., and different risk strategies exist for different sub-identity authentication risks.

[0130] According to embodiments of this disclosure, resource abuse risk can be a problem involving the unnecessary waste of resources multiple times, such as repeatedly unbinding cards, repeatedly querying the same information, etc. The target attribute data corresponding to resource abuse risk can be unbinding, binding, etc.

[0131] According to embodiments of this disclosure, transaction risks may include situations where there is a risk of transaction denial, such as users denying transactions that have been processed or conducted. The target attribute data corresponding to transaction authentication risks may be electronic signatures, SMS notifications, etc.

[0132] According to embodiments of this disclosure, by comparing target attribute data with a preset database, risk strategies that may be needed in business operations can be determined comprehensively and quickly, thereby preventing potential security threats in all aspects.

[0133] According to embodiments of this disclosure, determining a business security strategy model based on a risk strategy and a corresponding processing strategy may include the following operations.

[0134] Based on the risk strategy, a strategy summary is generated; based on the strategy summary, a match is performed in a preset strategy table to obtain the matching result; if the matching result indicates that a strategy summary exists in the preset strategy table, the target processing strategy corresponding to the strategy summary is determined, wherein the preset strategy table includes the association relationship between multiple preset risk strategies and multiple preset processing strategies; based on the risk strategy and the target processing strategy, a business security strategy model is generated.

[0135] According to the embodiments of this disclosure, the method for generating the strategy summary is not limited and can be any method that can generate the strategy summary, such as keyword extraction.

[0136] According to the embodiments of this disclosure, after determining the risk strategy, a strategy summary is generated for each risk strategy. The strategy summary is matched against a preset strategy table to obtain a matching result. If the matching result indicates that a strategy summary exists in the preset strategy table, the target processing strategy corresponding to the strategy summary can be determined. A business security strategy model is generated by organizing the risk category, risk strategy, and target processing strategy. The business security strategy model can be as shown in Table 5.

[0137] Table 5

[0138]

[0139] According to embodiments of this disclosure, the business security strategy model can directly and comprehensively determine the risk strategies that should be used in business processing and how to handle these risk strategies. This avoids the problem of mismatch between risk strategies and handling strategies and business needs, reduces the problem of insufficient security authentication leading to business vulnerabilities due to overly lenient risk strategies and handling strategies in business scenarios, and reduces the problem of low usability or high cost in subsequent actual use due to overly lenient security strategies in business scenarios. This better improves the matching degree of risk strategies and handling strategies with business scenarios.

[0140] Figure 6 The diagram illustrates a business security policy generation method according to another embodiment of this disclosure.

[0141] like Figure 6 As shown, based on the data type of the business sub-data 610 included in the business data, the first target business sub-data is determined, and then the first target business sub-data is processed according to the data format of the first target business sub-data to obtain risk sub-data 620.

[0142] According to an embodiment of this disclosure, a security attribute table 640 is obtained based on risk sub-data 620 and second target business sub-data 630.

[0143] According to embodiments of this disclosure, target attribute data is determined from multiple attribute data included in security attribute table 640, and then a risk strategy corresponding to the target attribute data is determined from a preset risk database; finally, based on the risk strategy, a target processing strategy corresponding to the risk strategy is determined from a preset strategy table, thereby determining a business security strategy model 650.

[0144] According to embodiments of this disclosure, a target security attribute table is determined from the security attribute table, specifying the security type as regional security type and object security type, and a security trust model 660 is generated using the target security attribute table.

[0145] Based on the above-described method for generating business security policies, this disclosure also provides a device for generating business security policies. The following will be combined with... Figure 7 The device is described in detail.

[0146] Figure 7 A schematic block diagram of a business security policy generation apparatus according to an embodiment of the present disclosure is shown.

[0147] like Figure 7 As shown, the business security policy generation device 700 in this embodiment includes a security attribute generation module 710, a target data determination module 720, a risk policy determination module 730, and a policy model determination module 740.

[0148] The security attribute generation module 710 is used to generate a security attribute table in response to receiving business data, based on the data type of the business sub-data included in the business data.

[0149] The target data determination module 720 is used to determine target attribute data from multiple attribute data included in the security attribute table.

[0150] The risk strategy determination module 730 is used to determine the risk strategy corresponding to the target attribute data from the preset risk database, wherein the preset risk database includes the association between the target attribute data and the risk strategy.

[0151] The strategy model determination module 740 is used to determine a business security strategy model based on the risk strategy and the target processing strategy corresponding to the risk strategy.

[0152] According to embodiments of this disclosure, the security attribute generation module 710 further includes a first determination submodule, a risk determination submodule, and a security attribute determination submodule.

[0153] The first determining submodule is used to determine the first target business sub-data based on the data type of the business sub-data included in the business data.

[0154] The risk determination submodule is used to determine risk sub-data based on the data format of the first target business sub-data.

[0155] The security attribute determination submodule is used to generate a security attribute table based on the risk sub-data and the second target business sub-data, wherein the second target business sub-data is the business sub-data other than the first target business sub-data in the business sub-data.

[0156] According to embodiments of this disclosure, the risk determination submodule further includes a title determination unit, a candidate data determination unit, a target data determination unit, and a first risk determination unit.

[0157] The title determination unit is used to determine the target data title from the plurality of data titles based on a preset data identifier when the data format of the target business sub-data is a file format.

[0158] The candidate data determination unit is used to determine candidate risk data based on the target data title.

[0159] The target data determination unit is used to determine target candidate risk data from the candidate risk data based on regular expressions.

[0160] The first risk determination unit is used to determine risk sub-data from the plurality of target candidate risk data based on a preset risk data table.

[0161] According to embodiments of this disclosure, the risk determination submodule further includes a word segmentation unit, a probability determination unit, and a second risk determination unit.

[0162] The word segmentation unit is used to segment the target business sub-data into words to obtain at least one sub-data word segmentation sequence.

[0163] A probability determination unit is used to input the at least one sub-data segmentation sequence into a trained language model to obtain the probability value of the sub-data segmentation sequence being the risk sub-data.

[0164] The second risk determination unit is used to use the sub-data word segmentation sequence as the risk sub-data when the probability value is greater than or equal to the target threshold.

[0165] According to embodiments of this disclosure, the target data module 720 further includes a title determination submodule and a target data determination submodule.

[0166] The title determination submodule is used to determine the target title from the security data table based on the security type.

[0167] The target data determination submodule is used to determine target attribute data based on the target title.

[0168] According to embodiments of this disclosure, the target data module 720 further includes a security attribute determination submodule and a security model generation submodule.

[0169] The security attribute determination submodule is used to determine the target security attribute table for security types of geographic security and object security.

[0170] The security model generation submodule is used to generate a security trust model based on the target security attribute table, so as to determine the trusted objects in the business processing process based on the security trust model.

[0171] According to embodiments of this disclosure, the risk strategy determination module 730 further includes a first matching submodule, a category determination submodule, and a strategy determination submodule.

[0172] The first matching submodule is used to match the target attribute data with the preset risk database to obtain the matching result.

[0173] The category determination submodule is used to determine the risk category of the target attribute data when the matching result indicates that the target attribute data exists in the preset risk database.

[0174] The strategy determination submodule is used to determine the risk strategy based on the risk categories, wherein the risk categories include sensitive information risk, identity authentication risk, resource abuse risk, and transaction risk.

[0175] According to embodiments of this disclosure, the strategy model determination module 740 further includes a summary generation submodule, a second matching submodule, a target strategy determination submodule, and a strategy model generation submodule.

[0176] The summary generation submodule is used to generate a strategy summary based on the risk strategy.

[0177] The second matching submodule is used to perform matching in a preset policy table based on the policy summary to obtain the matching result.

[0178] The target strategy determination submodule is used to determine the target processing strategy corresponding to the strategy summary when the matching result indicates that the strategy summary exists in the preset strategy table. The preset strategy table includes the association relationship between multiple preset risk strategies and multiple preset processing strategies.

[0179] The strategy model generation submodule is used to generate the business security strategy model based on the risk strategy and the target processing strategy.

[0180] According to embodiments of this disclosure, any plurality of modules among the security attribute generation module 710, target data determination module 720, risk strategy determination module 730, and strategy model determination module 740 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the security attribute generation module 710, target data determination module 720, risk strategy determination module 730, and strategy model determination module 740 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the security attribute generation module 710, target data determination module 720, risk strategy determination module 730, and strategy model determination module 740 can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.

[0181] Figure 8 A block diagram schematically illustrates an electronic device suitable for implementing a business security policy generation method according to an embodiment of the present disclosure.

[0182] like Figure 8 As shown, an electronic device 800 according to an embodiment of this disclosure includes a processor 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage portion 808 into a random access memory (RAM) 803. The processor 801 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 801 may also include onboard memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this disclosure.

[0183] RAM 803 stores various programs and data required for the operation of electronic device 800. Processor 801, ROM 802, and RAM 803 are interconnected via bus 804. Processor 801 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 802 and / or RAM 803. It should be noted that the programs may also be stored in one or more memories other than ROM 802 and RAM 803. Processor 801 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.

[0184] According to embodiments of this disclosure, the electronic device 800 may further include an input / output (I / O) interface 805, which is also connected to a bus 804. The electronic device 800 may also include one or more of the following components connected to the input / output (I / O) interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the input / output (I / O) interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 810 as needed so that computer programs read from it can be installed into the storage section 808 as needed.

[0185] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0186] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 802 and / or RAM 803 and / or one or more memories other than ROM 802 and RAM 803 described above.

[0187] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the item recommendation method provided in the embodiments of this disclosure.

[0188] When the computer program is executed by the processor 801, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0189] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 809, and / or installed from a removable medium 811. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0190] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by processor 801, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0191] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0192] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0193] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0194] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A method for generating a business security policy, comprising: In response to receiving business data, a security attribute table is generated based on the data type of the business sub-data included in the business data; Determine the target attribute data from the multiple attribute data included in the security attribute table; The risk strategy corresponding to the target attribute data is determined from a preset risk database, wherein the preset risk database includes the association between the target attribute data and the risk strategy; Based on the risk strategy and the target processing strategy corresponding to the risk strategy, a business security strategy model is determined; The step of generating a security attribute table based on the data type of the business sub-data included in the business data includes: Based on the data type of the business sub-data included in the business data, determine the first target business sub-data; Based on the data format of the first target business sub-data, determine the risk sub-data; Based on the risk sub-data and the second target business sub-data, a security attribute table is generated, wherein the second target business sub-data refers to the business sub-data other than the first target business sub-data.

2. The method according to claim 1, wherein, The data format of the first target business sub-data includes a file format, and the first target business sub-data includes multiple data headers; The determination of risk sub-data based on the data format of the first target business sub-data includes: When the data format of the first target business sub-data is a file format, the target data title is determined from the plurality of data titles based on a preset data identifier; Based on the target data title, candidate risk data are determined; Based on regular expressions, target candidate risk data is determined from the candidate risk data; Based on a preset risk data table, risk sub-data is determined from the multiple target candidate risk data.

3. The method according to claim 1, wherein, The data format of the first target business sub-data includes text format; The determination of risk sub-data based on the data format of the first target business sub-data includes: When the data format of the first target business sub-data is text format, the first target business sub-data is segmented into words to obtain at least one sub-data segmentation sequence; The at least one sub-data segmentation sequence is input into the trained language model to obtain the probability value of the sub-data segmentation sequence being the risk sub-data; If the probability value is greater than or equal to the target threshold, the segmented sequence of the sub-data will be used as the risk sub-data.

4. The method according to claim 1, wherein, The security attribute table includes security types corresponding to the security attribute table; Determining the target attribute data from the multiple attribute data included in the security attribute table includes: Based on the security type, the target title is determined from the security attribute table; Based on the target title, the target attribute data is determined.

5. The method according to claim 4, wherein the security attribute table is at least one, and the method further comprises: Determine the target security attribute table with security types of geographic security and object security; Based on the target security attribute table, a security trust model is generated to identify trusted objects in the business processing.

6. The method according to claim 1, wherein, The step of determining the risk strategy corresponding to the target attribute data from a preset risk database includes: The target attribute data is matched with the preset risk database to obtain the matching result; If the matching result indicates that target attribute data exists in the preset risk database, the risk category of the target attribute data is determined; Based on the risk categories, the risk strategy is determined, wherein the risk categories include sensitive information risk, identity authentication risk, resource abuse risk, and transaction risk.

7. The method according to claim 1, wherein, The process of determining a business security strategy model based on the risk strategy and the corresponding processing strategy includes: Based on the aforementioned risk strategy, a strategy summary is generated; Based on the policy summary, a matching process is performed in a preset policy table to obtain the matching result; If the matching result indicates that the strategy summary exists in the preset strategy table, the target processing strategy corresponding to the strategy summary is determined. The preset strategy table includes the association between multiple preset risk strategies and multiple preset processing strategies. Based on the risk strategy and the target processing strategy, the business security strategy model is generated.

8. A business security policy generation apparatus, comprising: A security attribute generation module is used to generate a security attribute table in response to received business data, based on the data type of the business sub-data included in the business data. The target data determination module is used to determine target attribute data from multiple attribute data included in the security attribute table; A risk strategy determination module is used to determine the risk strategy corresponding to the target attribute data from a preset risk database, wherein the preset risk database includes the association between the target attribute data and the risk strategies; and The strategy model determination module is used to determine a business security strategy model based on the risk strategy and the target processing strategy corresponding to the risk strategy; The security attribute generation module includes: The first determining submodule is used to determine the first target business sub-data based on the data type of the business sub-data included in the business data; The risk determination submodule is used to determine risk sub-data based on the data format of the first target business sub-data; The security attribute determination submodule is used to generate a security attribute table based on the risk sub-data and the second target business sub-data, wherein the second target business sub-data is the business sub-data other than the first target business sub-data in the business sub-data.

9. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for determining risk control strategy based on predictive model and related device

    CN109034660A